With Copilot
Acquia Copilot is a conversational AI connected into our product documentation and knowledge base. Ask Copilot about product features, technical details, troubleshooting and how to get started with Acquia products.
Sign in to use Acquia Copilot
Security is important for every website. When employees leave a project or company for whatever reason, you must review their security access to prevent potential future tampering or the loss of important data. Failure to secure your subscription after an employee departure can result in issues like the following:
If you are a Cloud Platform subscriber, review the following steps to secure your websites after an employee’s departure:
Remove the employee from your Acquia Teams
The subscription administrator should remove the employee from all teams. If the administrator is the departing employee, the departing employee can designate a new organization owner. If this isn’t possible, create a Support ticket and copy the previous owner on the ticket for an easier transition, if possible. If the previous owner is unavailable, see Transferring ownership from an unavailable owner.
Click Users and SSH Keys.
This displays the Users and keys page.
Remove the employee from any elevated roles on your websites
Check any single sign-on solutions your organization uses.
Remove the employee’s entries from the Teams and Permissions pages
For information about how to do this, see Transferring ownership of an organization. For information about completely deleting a user account from Cloud Platform, see GDPR Data Subject Rights requests.
Update credentials in Pipelines
Pipelines performs jobs with the credentials of the user who first performs a Pipelines job for that subscription. If the departing employee provided the credentials for your subscription, your Pipelines jobs may fail. For more information, see User permission issues.
Be sure to review the following items to secure your website after an employee’s departure:
Change any administrative passwords to which the employee had access
Affected passwords can include the website itself, shell accounts, and phpMyAdmin.
Review the Drupal roles and permissions
Edit the employee’s account in your Drupal website, and change their access to a lower permission level, or set it to blocked.
Review recent code changes
If the parting is less than amicable, a departing individual may commit code allowing continued access to the website through a back door.
Change the salt for your encryption
For more information about encryption salting, see this Wikipedia article.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
If this content did not answer your questions, try searching or contacting our support team for further assistance.